CVE-2020-23887: Medium severity xnview mp vulnerability
Published Nov 10, 2021
·Updated
XnView MP v0.96.4 was discovered to contain a heap overflow which allows attackers to cause a denial of service (DoS) via a crafted ico file. Related to a Read Access Violation starting at USER32!SmartStretchDIBits+0x33.
Affected Software
1 affected component
XnView MP<=0.96.4
Event History
Nov 10, 2021
CVE Published
via MITRE·09:25 PM
Data Sourced
via MITRE·09:25 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-23887.
2
What is the severity of CVE-2020-23887?
The severity of CVE-2020-23887 is classified as medium with a severity value of 5.5.
3
What is the affected software for CVE-2020-23887?
XnView MP version 0.96.4 is the affected software for CVE-2020-23887.
4
What is the impact of CVE-2020-23887?
CVE-2020-23887 allows attackers to cause a denial of service (DoS) via a crafted ico file.
5
Is there a fix available for CVE-2020-23887?
At the time of writing, there is no known fix available for CVE-2020-23887. It is recommended to update to the latest version of XnView MP when a fix becomes available.